3 hours ago
My service on *.up.railway.app receives X-Forwarded-For with 2 entries, where the right-hand entry is a CDN77 address (152.233.46.0/23, NYC). A request with a spoofed X-Forwarded-For still arrives with 2 entries, so your edge appears to strip client-supplied values. To configure Express trust proxy safely, I'd like to know: (1) which IP ranges your CDN layer uses, or a list I can reference; (2) whether client-supplied XFF is stripped on both the CDN route and the direct route. Thanks!
1 Replies
3 hours ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 3 hours ago
3 hours ago
There isn't a documented CIDR range for proxies.
Also, headers like X-Forwarded-For and X-Real-IP is written at the edge, so it can't be spoofed.
